SCS-C02 exam dumps

SCS-C02 practice question 11 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 11

Select 2

Your company is using Amazon S3 to store sensitive financial data. You have been tasked with ensuring that the S3 bucket containing this data is secure and compliant with the company's data protection policies. Which actions should you take to secure the bucket and meet compliance requirements? (Select TWO)

  1. A

    Enable Server-Side Encryption (SSE) with AWS Key Management Service (KMS) for the bucket.

  2. B

    Configure the bucket to allow public read access for certain files to facilitate external sharing.

  3. C

    Enable logging for the bucket using AWS CloudTrail to track S3 API requests.

  4. D

    Use an AWS WAF web ACL to protect the bucket from unauthorized access.

  5. E

    Implement an S3 bucket policy that grants access only to specific IAM roles or users.

Show answer and explanation

Correct answers: A, E

Explanation

To secure an S3 bucket containing sensitive data, it is essential to implement encryption (such as SSE with KMS) to protect data at rest and use precise access controls (via bucket policies or IAM roles) to restrict access to authorized users only. Both of these measures align with AWS security best practices for data protection and compliance requirements. Other options, such as enabling logging or using AWS WAF, while helpful in their own contexts, do not directly address bucket security for sensitive data.

  • A. Correct.

    Enabling Server-Side Encryption (SSE) with AWS KMS ensures that all data stored in the bucket is encrypted at rest with a managed key. This is a key security and compliance measure.

  • B. Incorrect.

    Allowing public read access contradicts security best practices for sensitive data. Public access should be strictly avoided unless explicitly needed and justified.

  • C. Incorrect.

    While enabling CloudTrail logging is useful for tracking and auditing API requests, it does not directly secure the bucket. It is a monitoring tool rather than a security control.

  • D. Incorrect.

    AWS WAF is used to protect web applications from common web exploits, not S3 buckets. S3 bucket policies and IAM permissions are the appropriate mechanisms for securing access to an S3 bucket.

  • E. Correct.

    Implementing an S3 bucket policy to restrict access to specific IAM roles or users ensures that only authorized entities can access the bucket, which is a critical security best practice.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam